[5805] in bugtraq
Re: Buffer overrun in Redhat 5.0
daemon@ATHENA.MIT.EDU (Ask =?iso-8859-1?Q?Bj=F8rn?= Hanse)
Tue Dec 16 05:43:26 1997
Date: Tue, 16 Dec 1997 00:28:54 +0100
Reply-To: Ask =?iso-8859-1?Q?Bj=F8rn?= Hansen <ask@NETCETERA.DK>
From: Ask =?iso-8859-1?Q?Bj=F8rn?= Hansen <ask@NETCETERA.DK>
X-To: Wilton Wong - ListMail <listmail@nova.blackstar.net>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <Pine.LNX.3.96.971215063234.3687A-100000@nova.blackstar.net>
>Okay I noticed that if I ran tracroute with a really long param it
>segfaults and I wondered if I could exploit this, I could, I checked to
>see that I didn't have a twisted version of traceroute, I didn't, so I
>tried ping as well same result. That's when I posted.
From the redhat website (errata page for redhat 5.0):
Package: traceroute
Updated: 15-Dec-1997
Problem:
(15-Dec-1997) Security Fix: Fixes buffer overruns in traceroute.
Solution:
Intel: Upgrade to traceroute-1.4a5-5.i386.rpm
Alpha: Upgrade to traceroute-1.4a5-5.alpha.rpm
I would guess that it's this problems they have fixed. Better ask someone
at redhat...
kind regards,
ask
---------------------------------------------------------------------
ask bjoern hansen - Netcetera - Finsensvej 80 - DK-2000 Frederiksberg
tlf 38 88 32 22 / 40 44 58 66 / 38 88 20 38 ext 341 - Fax 38 88 30 38
Webdesign, Webhotel, Mailhotel, UUCP & more! http://www.netcetera.dk/